Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 195571 - www-servers/tomcat < 5.5.25 Multiple information disclosures (CVE-2007-{3382,3385})
Summary: www-servers/tomcat < 5.5.25 Multiple information disclosures (CVE-2007-{3382,...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/26466/
Whiteboard: B4 [noglsa]
Keywords:
: 195563 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-10-12 01:49 UTC by Robert Buchholz (RETIRED)
Modified: 2007-11-12 21:50 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2007-10-12 01:49:54 UTC
CVE-2007-3382 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3382):
  Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to
  4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies,
  which might cause sensitive information such as session IDs to be leaked and
  allow remote attackers to conduct session hijacking attacks.

CVE-2007-3385 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3385):
  Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to
  4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence
  in a cookie value, which might cause sensitive information such as session
  IDs to be leaked to remote attackers and enable session hijacking attacks.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-10-12 01:58:28 UTC
*** Bug 195563 has been marked as a duplicate of this bug. ***
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2007-10-12 02:01:49 UTC
Sorry for rudely closing the other bug.

Arches, please test and mark stable www-servers/tomcat-5.5.25 and its deps:
dev-java/eclipse-ecj-3.3.0-r1
dev-java/tomcat-servlet-api-5.5.25

Target keywords are: "amd64 x86 ~x86-fbsd"
Comment 3 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-10-12 02:47:55 UTC
amd64 stable 
Comment 4 Christian Faulhammer (RETIRED) gentoo-dev 2007-10-12 08:32:13 UTC
x86 stable, last arch, open for GLSA vote
Comment 5 Christian Faulhammer (RETIRED) gentoo-dev 2007-10-12 10:15:57 UTC
Adding BSD back, your KEYWORD is missing.  Anyway, GLSA vote is still valid.
Comment 6 Roy Marples (RETIRED) gentoo-dev 2007-10-12 11:35:19 UTC
Added our keyword back. Next time a bsd keyword gets dropped please say so on the bug as we automatically remove ourselves on stable requests as we have no stable keyword at this time.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-10-17 19:27:40 UTC
I tend to vote NO.
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-10-17 22:21:52 UTC
I vote NO.
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2007-11-12 21:50:48 UTC
Voting no and closing. Feel free to reopen if you disagree.